|

AI asset inventory: the discipline the AI Act postponement doesn’t change

Two calendars showing August 2026 and December 2027 beside a file labelled EU AI Act Omnibus
AI asset inventory table with owner, risk class and review date columns: the auditable register the EU AI Act requires
An auditable AI asset inventory: each row documents owner, risk class and review date.

When the AI Omnibus agreement was reached on 7 May, I received half a dozen messages with the same question: “so we stop until 2027, right?”. My answer was short: no. What is postponed is the full conformity of high-risk systems. What is not postponed is the AI asset inventory, which is where any serious compliance programme begins.

I will tell it as I encounter it in these conversations, because there is a confusion ingrained among management that is worth clearing up before it becomes a real problem.

What the AI Act postponement means for your inventory

Two calendars showing August 2026 and December 2027 next to a folder labelled EU AI Act Omnibus
A double regulatory horizon after the AI Omnibus: August 2026 and December 2027.

The AI Omnibus has moved dates, it has not dismantled the regulation. There are three obligations that remain exactly where they were, and which your AI asset inventory should be able to answer for by August 2026:

  • AI literacy (Article 4) · August 2026. Fines of up to 15 million euros or 3% of global turnover.
  • Generative AI transparency (Article 50) · August 2026. Operational watermarking in new systems. December 2026 for those already on the market.
  • Prohibited practices (Article 5) · in force since February 2025. Fines of up to 35 million or 7%.

The full detail of the timeline and of what has been postponed I explained in the analysis of the postponement of the European AI law, where the inventory appears as priority no. 2 of the five I recommend closing before August. This article develops that priority in detail, because it is the basis on which the other four rest.

My position is direct. The extra 16 months until December 2027 are not room to postpone. They are room to build well what in August last year was impossible to do with incomplete standards.

AI asset inventory is not the same as Shadow AI

It is worth clarifying the line before getting into the subject, because they are two distinct disciplines and they are often confused in committees.

Shadow AI in the company is the problem of unauthorised adoption: employees using ChatGPT, Claude or various assistants without IT or compliance being aware. You solve it with a tool catalogue, sandbox, training and an acceptable use policy.

The AI asset inventory is the complementary problem and, in my experience, far less attended to: the AI systems that are authorised, operational in production, integrated into business processes and to which no one assigns a review date. The difference matters because the response is completely different: here it is not about training employees, it is about building a living register and a formal life cycle.

A company can have shadow AI reasonably under control and, at the same time, have no idea how many production models are supporting business decisions right now. I see it every week.

Why the inventory is the first step, not the last

In 30 years leading IT projects in banking, insurance and public administration, the most expensive lesson to learn has always been the same. What the organisation pays for in an audit is not what fails in the AI asset inventory. It is what it did not know it had.

With AI this is being reproduced at accelerated speed. Recent industry reports suggest that only one in four organisations has taken at least 40% of its AI initiatives to production. What most do not ask is what happens to that 40%: where it is registered, who audits it, who decides when it is retired.

That is why I put it to management this bluntly: if the inventory does not exist in August 2026, the plan for December 2027 cannot be written. It is not a question of haste, it is one of order. Without an inventory there is no risk classification; without classification there is no application of Article 17; without Article 17 there is no quality management system. The chain starts with inventorying.

What goes into an AI asset inventory

The six columns of the AI asset inventory: ID, purpose, data sources, risk classification, owner and review date
The six minimum columns that separate a living inventory from a dead PDF in SharePoint.

A useful inventory — auditable, not decorative — must answer six questions for each system. I say this because I have seen inventories fail both from an excess of columns and from a lack of the right ones. These are the ones that matter:

The six columns of the AI asset inventory

  • System identification. Name, version, provider or base model. An agent on GPT-4o is not the same as one on Claude Opus 4.7. And the version changes obligations.
  • Purpose and use case. What decision it supports or automates. Without this, the risk cannot be classified under Annex III.
  • Training and operation data. What it consumes, from what source, with what GDPR legal basis. If there are personal data, there are additional obligations.
  • EU AI Act risk classification. Prohibited, high, limited or minimal. The classification determines practically all the subsequent obligations.
  • Technical owner and business owner. Two people with first and last names. If the person responsible is “the IT team”, there is no one responsible.
  • Review date and planned retirement date. This is what almost no one has and what distinguishes a living inventory from a dead PDF in SharePoint.

The sixth is the column that separates operational inventories from those generated once and forgotten. An AI asset without a review date is an orphan asset waiting to be audited. And it connects with the other problem I already analysed about AI agents in regulated environments: the more autonomous the system, the more critical it becomes to keep that date alive.

A case of my own: the asset no one had given a review date

I tell it because it illustrates exactly that sixth column of the AI asset inventory, not because it is epic.

A few months ago, in a routine audit of my own infrastructure, I detected an unusual load spike on one of my servers. The diagnosis identified three AI widgets connected to an external API, running on secondary landing pages since their initial deployment. They were documented. They had a technical owner. They met the first five columns of the inventory.

What they did not have was the sixth. No one had set a review date. Months went by without anyone looking at them. When I checked the real traffic of those landings, the three together added up to less than one click a day. The API key was still alive, with billing permissions. They were working fine, but they had not been justified again since their origin.

The right decision — and this is where discipline matters — was to retire them. I revoked the key, deactivated the endpoints, deleted the files, documented the removal. Not because AI was the problem, but because they were assets without a living review process. If they had had a three-month review date, the system itself would have forced me to make the decision in time.

An AI asset without a next review date is not a managed asset. It is a regulatory liability waiting to be discovered.

Retirement as a discipline, not an exception

AI asset life cycle in five phases: inventory, deploy, monitor, review and retire, the last highlighted in amber
AI asset life cycle: retirement is the phase almost no one plans.

The AI asset inventory connects directly with Article 17 of the AI Act, which comes into force with the rest of the Annex III obligations on 2 December 2027 and defines the quality management system for high-risk systems. What most commentators overlook is that a quality management system includes, by definition, the phase of controlled asset retirement. ISO 42001 — the AI management system standard that is moving from “interesting” to “necessary” in many enterprise purchasing conversations — formalises it explicitly.

Retiring an AI system properly is not about hitting delete. It involves:

  • Revoking associated credentials and API keys.
  • Archiving audit logs according to the applicable retention period.
  • Documenting the decision and its justification.
  • Notifying dependent users or processes.
  • Updating the inventory with the date and reason for removal.

In regulated sectors, the traceability of retirement is as required as that of deployment. NIS2 frames it as a risk-management obligation in its Article 21: measures proportionate to the risk throughout the full life cycle of the asset. For financial entities, DORA is added, which in its Article 8 requires maintaining a consolidated register of ICT assets, including those based on AI. A live asset that is not managed is a documented breach under three frameworks at once.

Three questions for your next AI committee

If you lead an AI committee, govern AI asset inventory compliance or are assessing whether your organisation will make the most of the Omnibus’s extra 16 months instead of spending them, these are the three questions worth being able to answer before next quarter:

  • How many AI systems do we have in production and who is the owner of each one? If the answer takes more than a week or requires asking by email, there is no inventory.
  • What is the next review date of each of those systems? Without a date, there is no life cycle. Without a life cycle, there is no framework you can prepare for Article 17 in December 2027.
  • How many AI assets have we retired in the last twelve months and where is the traceability? If the answer is zero, it is not that there is nothing to retire. It is that no one is looking.

The organisations that will reach December 2027 with room to spare are not the ones that invest the most in AI. They are the ones using this year to build what is not postponed: inventory, classification, ownership, life cycle. Those using the postponement as an excuse to do nothing will find themselves, in December 2027, exactly where they are today. With the difference that the fines will be real and the market much more demanding.

Frequently asked questions about AI asset inventory

Build the inventory before the audit builds it for you

Do you need to build the AI asset inventory and the life cycle your organisation should have closed before August? It is exactly what I do: I help companies in regulated sectors turn the AI Act into an executable programme, with an auditable inventory, clear ownership and real traceability. If you want to work on it with me, write to me here and I will reply personally.

Do you have to apply this under DORA, NIS2 or ENS? Tell me about it.

Book 20 minutes

Leave a Reply

Your email address will not be published. Required fields are marked *